Tusen Takk Tusen Takk

Privacy Policy

As of: May 2026

1 Controller

The controller within the meaning of the General Data Protection Regulation ("GDPR") is:

Constantin Hirt
Gasborn 23
52062 Aachen, Germany
Email: hello@tusentakk.app

2 Scope

This Privacy Policy applies to the mobile application "Tusen Takk" (iOS, and potentially Android) and the website tusentakk.app.

3 What data we process

3.1 Account and profile data

During registration and use, we process the following data:

3.2 Transaction and activity data

3.3 Device and technical data

4 Purposes and legal bases for processing

PurposeLegal basis
Provision of the app, authentication and account managementArt. 6(1)(b) GDPR (performance of contract)
Processing of gift transactions including redemption and payoutArt. 6(1)(b) GDPR
Display of selfies to the Sender for approvalArt. 6(1)(b) GDPR; where applicable Art. 9(2)(a) GDPR (consent), see section 6
Push notificationsArt. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR
Points, levels and leaderboard functionArt. 6(1)(b) GDPR
Server logs for IT securityArt. 6(1)(f) GDPR (legitimate interest)
Compliance with legal obligations (e.g. information and retention obligations)Art. 6(1)(c) GDPR

5 Recipients and processors

We share personal data with recipients only where this is necessary for the provision of the service or a legal obligation exists. The following processors and independent recipients are used:

Transfer of data to third countries outside the EU/EEA takes place only on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.

6 Processing of the Redemption Selfie

To evidence that a Recipient has actually redeemed the gift assigned to them, the Recipient uploads a photo (typically a selfie with the gift) during the redemption process. This photo is shown exclusively to the Sender of the gift for confirmation.

Purpose of processing: Evidence of actual redemption to enable the Sender to release the payment.

Legal basis: Art. 6(1)(b) GDPR (execution of the user-initiated redemption process) as well as Art. 6(1)(a) GDPR (consent through deliberate upload). To the extent that a selfie contains facial features that may in individual cases be classified as biometric data within the meaning of Art. 9 GDPR, the processing is additionally based on explicit consent pursuant to Art. 9(2)(a) GDPR.

Retention period: The photo is automatically deleted from our systems 30 days after the final confirmation by the Sender. If the Sender does not confirm the redemption, deletion occurs 30 days after upload. The Recipient may delete the photo at any earlier time.

Data recipients: The photo is shown exclusively to the Sender of the respective gift. No automated facial recognition, no biometric matching, and no disclosure to third parties takes place.

Withdrawal and deletion: The Recipient may withdraw consent at any time and request immediate deletion of the photo, without any reason being required. Contact: hello@tusentakk.app.

7 Storage periods

8 Your rights

You have the right at any time to:

To exercise your rights, a simple message to hello@tusentakk.app or use of the "Delete account" function in the app (Profile → Settings) is sufficient.

9 Security

10 Automated decisions and profiling

No exclusively automated decision-making within the meaning of Art. 22 GDPR takes place. The approval of a selfie is always carried out manually by the Sender. Points are awarded according to fixed rules and do not lead to legal or comparably significant effects.

11 Changes to this Privacy Policy

We reserve the right to update this Privacy Policy when app functions change or the legal situation requires it. Material changes will be communicated via the app or by email.

12 Data protection contact

For questions about data protection or to exercise your rights, please contact us at:

Constantin Hirt — Data Protection
Gasborn 23
52062 Aachen
Email: hello@tusentakk.app